Live data from Hacker News

Pakistan bans VPNs

tribune.com.pk

51–60 of 63 posts

Re: Pakistan bans VPNs

#51

Earlier quoted context omitted.

I believe that blake8086 was referring to the content of the hidden message when he said plain text. He is asserting that if you hide 'hidden message here' in something, you are using security by obscurity, but if you try to hide ENC('hidden message here', 'secret key goes here') you are going to make the detection of the presence of your secret message easier.

I argued against the latter point: if you hide the encrypted message in something which is normally compressed such as JPEG or DivX, the encrypted message blends in with the rest of the data because compressed data has high entropy (the better the compression, the higher the entropy). I don't get your point about security by obscurity, that's pretty much the whole point of steganography I would suppose. Security by o…

You need to quantify "blends in". If I [an attacker] plot a distribution of the entropy in all your files, and some of them are outliers, even by a small amount, I can focus all my analysis on those files.

Re: Pakistan bans VPNs

#52

Earlier quoted context omitted.

If you use steganography with plaintext, you're relying on security by obscurity. Governments aren't going to tell you when they've cracked your secret. If you're encrypting your steganographic messages, you're increasing the entropy of the plaintext message you're concealing it in.

If you use steganography with plaintext, you're relying on security by obscurity. No. It is perfectly possible to have steganographic keys, in the same way that you have cryptographic keys. Trivial example: If the key is 7, the hidden message can be extracted by combining the least significant bits of every 7th pixel of an image. (Incidentally, that hidden message could also be, and indeed probably should also be, en…

How does this differ significantly from a grille ( http://en.wikipedia.org/wiki/Grille_(cryptography) )?

Re: Pakistan bans VPNs

#53

In Iran, in the days we had protests, they dropped all encrypted connections as well. That makes internet simply unusable. I hope this would never come to Iran, although I believe it will. Soon.

I am sorry to hear that, my friend. Godspeed.

Re: Pakistan bans VPNs

#54

In Iran, in the days we had protests, they dropped all encrypted connections as well. That makes internet simply unusable. I hope this would never come to Iran, although I believe it will. Soon.

What about the possibility of encrypted traffic that doesn't look encrypted? Perhaps "Liking" public Facebook status updates such that the first letter of each status liked, in chronological order, is the datastream.

Re: Pakistan bans VPNs

#55
post #54

In Iran, in the days we had protests, they dropped all encrypted connections as well. That makes internet simply unusable. I hope this would never come to Iran, although I believe it will. Soon.

What about the possibility of encrypted traffic that doesn't look encrypted? Perhaps "Liking" public Facebook status updates such that the first letter of each status liked, in chronological order, is the datastream.

While not encrypted, Iodine (http://code.kryo.se/iodine/) does a similar thing by putting data payload in DNS requests/responses.

Re: Pakistan bans VPNs

#56
post #27

Earlier quoted context omitted.

> Businesses of any size can't run without encrypted channels. Sure they can - they did before the internet. (No, the postal mail is not secure.) > Proceeding with this seems sure way to smother any economic development and relegate the country to third-world backwater status for the foreseeable future. And is any world leader crazy enough to do that besides Kim Jong-il? Pretty much every "world leader" in the last 1…

>Sure they can - they did before the internet. (No, the postal mail is not secure.) It's several orders of magnitude more secure than plain http. >Besides, the effect on economic development in the short term will be almost unnoticable. India has to be chock full of nationalistic script kiddies and legitimate hackers who will have a field day wrecking Pakistan's online economy if they actually try to implement this p…

As well they should. It's one thing to use your leet skillz on some bigco with the vague self-important notion that the man is oppressing the peepz, but how often do they get to go up against real, genuine Bad with a big b.

Anonymous has got some work to do.

Re: Pakistan bans VPNs

#57

Earlier quoted context omitted.

If you use steganography with plaintext, you're relying on security by obscurity. No. It is perfectly possible to have steganographic keys, in the same way that you have cryptographic keys. Trivial example: If the key is 7, the hidden message can be extracted by combining the least significant bits of every 7th pixel of an image. (Incidentally, that hidden message could also be, and indeed probably should also be, en…

How does this differ significantly from a grille ( http://en.wikipedia.org/wiki/Grille_(cryptography) )?

They are pretty similar.

Re: Pakistan bans VPNs

#59
OpenVPN sessions look like SSL traffic to the eavesdropper. So there's a good reason to use OpenVPN in Pakistan. They'll have to ban SSL at the state level as well.

Re: Pakistan bans VPNs

#60

This does nothing to stop people who are intent on communicating privately (SSL, SSH, public key encrypted messages, etc.) and everything to hamper internet progress in Pakistan. Why would a tech company even consider spreading/outsourcing to Pakistan after this?

For the same reason that they spread, for example, to China? If they think there is money to be made, you can't underestimate the concessions that a company will make to the local government.
Post reply on HN